Source catalog
September 17, 2026 · View on GitHub
184 authoritative sources, mapped to 150 skills. Each skill that has any carries its own list at references/sources.md inside the skill, which is where an agent reads it while answering.
References, never copies. The catalog holds a URL and a judgment about it, never source material. That is what keeps it live — a pointer to a regulator's site is right the moment the rule changes, and a snapshot is wrong the day after it is taken.
What you may do with it
125 of 184 are quotable, with attribution where the license asks for it. The rest are free to read and not free to reproduce, which is the single most useful thing this catalog records — most of what a professional must cite is not open.
| License | Sources | What an agent may do |
|---|---|---|
| Public domain (US government) | 92 | Quote freely |
| Public domain | 5 | Quote freely |
| CC BY | 8 | Quote with attribution |
| Open data | 1 | Use the data; read the terms before redistributing |
| Free to use with attribution | 19 | Quote with the publisher's required credit |
| CC BY-SA (share-alike) | 3 | Quote with attribution; do not fold into this repository |
| Free to read, all rights reserved | 46 | Read and cite only. Never reproduce. |
| Free behind an account | 5 | Cite it; the user fetches it. |
| Sold | 5 | Cite the identifier only, never the text. |
By subject
Data and workforce
| Source | Publisher | License | Skills |
|---|---|---|---|
| 29 CFR Part 1607 — Uniform Guidelines on Employee Selection Procedures | US Equal Employment Opportunity Commission | Public domain (US government) | data-analytics:ai-ml-governance, people:hiring-and-interviewing, people:performance-management |
| 29 CFR Part 541 — exemption regulations | US Department of Labor, Wage and Hour Division | Public domain (US government) | people:compensation-and-leveling, people:employment-compliance, people:org-design |
| 29 CFR Part 825 — Family and Medical Leave Act regulations | US Department of Labor, Wage and Hour Division | Public domain (US government) | people:benefits-and-leave, people:employment-compliance |
| 48 CFR Chapter 99 — Cost Accounting Standards | Cost Accounting Standards Board | Public domain (US government) | finance:cost-accounting |
| Apache Iceberg table specification | Apache Software Foundation | Free to use with attribution | data-analytics:data-engineering, data-analytics:data-modeling |
| Apache Parquet file format specification | Apache Software Foundation | Free to use with attribution | data-analytics:data-engineering |
| Artificial Intelligence and the ADA | US Equal Employment Opportunity Commission | Public domain (US government) | data-analytics:ai-ml-governance, people:hiring-and-interviewing |
| BLS Handbook of Methods | US Bureau of Labor Statistics | Public domain (US government) | data-analytics:quantitative-analysis, people:workforce-planning |
| Data Catalog Vocabulary | World Wide Web Consortium | Free to read, all rights reserved | data-analytics:chief-data-officer, data-analytics:data-engineering |
| ERISA — laws and regulations | US Department of Labor, Employee Benefits Security Administration | Public domain (US government) | people:benefits-and-leave |
| FIPS 140-3: Security Requirements for Cryptographic Modules | NIST | Public domain (US government) | security:data-protection-and-encryption |
| Federal Rules of Civil Procedure | Administrative Office of the US Courts | Public domain (US government) | legal-risk:disputes-and-legal-holds |
| General Records Schedules | US National Archives and Records Administration | Public domain (US government) | data-analytics:chief-data-officer, legal-risk:disputes-and-legal-holds |
| Handbook for Employers M-274: guidance for completing Form I-9 | US Citizenship and Immigration Services | Public domain (US government) | people:employment-compliance, people:onboarding-and-offboarding |
| IRS Publication 15-B: Employer's Tax Guide to Fringe Benefits | US Internal Revenue Service | Public domain (US government) | finance:tax, people:benefits-and-leave |
| ISO/IEC 42001 — AI management systems | ISO | Sold | data-analytics:ai-ml-governance |
| Interagency Guidance on Leveraged Lending, SR 13-3 | Board of Governors of the Federal Reserve System | Public domain (US government) | finance:capital-structure-and-covenants |
| NIST AI 600-1: Generative AI Profile | NIST | Public domain (US government) | data-analytics:ai-ml-governance, executive:ai-research-analyst |
| NIST AI RMF Playbook | NIST | Public domain (US government) | data-analytics:ai-ml-governance |
| NIST AI Risk Management Framework, AI 100-1 | NIST | Public domain (US government) | data-analytics:ai-ml-governance, data-analytics:chief-data-officer, executive:ai-research-analyst |
| NIST SP 800-57 Part 1: Recommendation for Key Management | NIST | Public domain (US government) | security:data-protection-and-encryption |
| NIST SP 800-92: Guide to Computer Security Log Management | NIST | Public domain (US government) | security:detection-and-monitoring |
| NIST/SEMATECH e-Handbook of Statistical Methods | NIST | Public domain (US government) | data-analytics:quantitative-analysis |
| NYSE Listed Company Manual | New York Stock Exchange | Free to read, all rights reserved | executive:fundraising-and-investor-relations, legal-risk:corporate-governance |
| O*NET database | National Center for O*NET Development, US Department of Labor | CC BY | people:learning-and-development, people:org-design, people:workforce-planning |
| OECD Recommendation of the Council on Artificial Intelligence | OECD | Free to use with attribution | data-analytics:ai-ml-governance |
| OpenLineage object model | LF AI and Data Foundation | Free to use with attribution | data-analytics:chief-data-officer, data-analytics:data-engineering |
| Shapes Constraint Language | World Wide Web Consortium | Free to read, all rights reserved | data-analytics:data-engineering, data-analytics:data-modeling |
| Statistical Quality Standards | US Census Bureau | Public domain (US government) | data-analytics:business-intelligence, data-analytics:quantitative-analysis |
| The Sedona Principles and Commentary on Legal Holds | The Sedona Conference | Free to read, all rights reserved | legal-risk:disputes-and-legal-holds |
Education
| Source | Publisher | License | Skills |
|---|---|---|---|
| C3 Framework for Social Studies State Standards | National Council for the Social Studies | Free to read, all rights reserved | education:standards-alignment |
| Common Core State Standards — English Language Arts and Literacy | NGA Center for Best Practices & CCSSO | Free to use with attribution | education:learning-materials-design, education:standards-alignment |
| Common Core State Standards — Mathematics | NGA Center for Best Practices & CCSSO | Free to use with attribution | education:assessment-design, education:standards-alignment |
| DocsTeach | US National Archives and Records Administration | Public domain (US government) | education:learning-materials-design |
| Head Start Early Learning Outcomes Framework, birth to five | US Department of Health and Human Services, Office of Head Start | Public domain (US government) | education:early-childhood-practice, education:standards-alignment |
| International Literacy Association position statements and briefs | International Literacy Association | Free to read, all rights reserved | education:assessment-design, education:learning-materials-design |
| Library of Congress classroom materials | Library of Congress | Public domain (US government) | education:learning-materials-design |
| NAEYC position statements, including Developmentally Appropriate Practice | National Association for the Education of Young Children | Free to read, all rights reserved | education:early-childhood-practice, education:learning-materials-design |
| NCTM Principles and Standards and position statements | National Council of Teachers of Mathematics | Free to read, all rights reserved | education:assessment-design, education:learning-materials-design |
| NGSS appendices — practices, crosscutting concepts, core ideas | NGSS Lead States / Achieve | Free to read, all rights reserved | education:standards-alignment |
| NSTA official positions | National Science Teaching Association | Free to read, all rights reserved | education:early-childhood-practice, education:standards-alignment |
| Next Generation Science Standards | NGSS Lead States / Achieve | Free to read, all rights reserved | education:assessment-design, education:standards-alignment |
| Standards for Mathematical Practice | NGA Center for Best Practices & CCSSO | Free to use with attribution | education:assessment-design, education:standards-alignment |
Finance and tax
| Source | Publisher | License | Skills |
|---|---|---|---|
| Applicable Federal Rates | US Internal Revenue Service | Public domain (US government) | finance:tax, finance:treasury-and-liquidity |
| COSO Internal Control — Integrated Framework | Committee of Sponsoring Organizations of the Treadway Commission | Sold | finance:internal-controls-and-audit, legal-risk:enterprise-risk |
| Daily Treasury Par Yield Curve Rates | US Department of the Treasury | Public domain (US government) | finance:capital-allocation, finance:financial-modeling, finance:treasury-and-liquidity |
| EDGAR full-text search and submissions API | US Securities and Exchange Commission | Public domain (US government) | corporate-strategy:mergers-and-acquisitions, finance:financial-reporting-and-close, finance:financial-statement-analysis |
| FASB Accounting Standards Codification | Financial Accounting Standards Board | Free behind an account | finance:chief-financial-officer, finance:financial-reporting-and-close, finance:revenue-recognition, revenue:pricing-and-packaging, revenue:revenue-operations |
| FRED — Federal Reserve Economic Data | Federal Reserve Bank of St. Louis | Open data | finance:budgeting-and-forecasting, finance:financial-modeling, finance:treasury-and-liquidity |
| IFRS Accounting Standards | IFRS Foundation | Free behind an account | finance:financial-reporting-and-close, finance:revenue-recognition |
| IRS forms, instructions and publications | US Internal Revenue Service | Public domain (US government) | finance:tax, people:payroll-operations |
| Internal Revenue Bulletin | US Internal Revenue Service | Public domain (US government) | finance:chief-financial-officer, finance:tax |
| PCAOB auditing standards | Public Company Accounting Oversight Board | Free to read, all rights reserved | finance:internal-controls-and-audit |
| State tax agency directory | Federation of Tax Administrators | Free to read, all rights reserved | finance:tax |
Legal and employment
| Source | Publisher | License | Skills |
|---|---|---|---|
| California Consumer Privacy Act — Attorney General | California Office of the Attorney General | Public domain | data-analytics:data-governance, legal-risk:privacy-and-data-protection |
| Consolidated State Minimum Wage and Overtime tables | US Department of Labor | Public domain (US government) | people:compensation-and-leveling, people:employment-compliance, people:payroll-operations |
| EEOC Laws, Regulations, Guidance and MOUs | US Equal Employment Opportunity Commission | Public domain (US government) | people:employee-relations, people:employment-compliance, people:hiring-and-interviewing |
| Electronic Code of Federal Regulations | US Government Publishing Office / NARA | Public domain (US government) | legal-risk:chief-legal-and-risk-officer, legal-risk:regulatory-compliance |
| European Data Protection Board guidelines and recommendations | EDPB | Free to use with attribution | data-analytics:data-governance, legal-risk:privacy-and-data-protection |
| Legal Information Institute | Cornell Law School | Free to read, all rights reserved | legal-risk:chief-legal-and-risk-officer, legal-risk:contract-review, legal-risk:regulatory-compliance |
| National Labor Relations Board — decisions and guidance | NLRB | Public domain (US government) | people:employee-relations, people:employment-compliance |
| OSHA law and regulations | US Occupational Safety and Health Administration | Public domain (US government) | legal-risk:regulatory-compliance, operations:business-continuity-and-resilience |
| Regulation (EU) 2016/679 — GDPR | Publications Office of the European Union | Free to use with attribution | data-analytics:data-governance, legal-risk:privacy-and-data-protection, legal-risk:regulatory-compliance |
| SPDX License List | The Linux Foundation | CC BY | legal-risk:intellectual-property, technology:release-and-deployment |
| State Labor Offices directory | US Department of Labor | Public domain (US government) | people:employment-compliance, people:payroll-operations |
| USPTO search and guidance | US Patent and Trademark Office | Public domain (US government) | legal-risk:intellectual-property |
| United States Code | Office of the Law Revision Counsel, US House of Representatives | Public domain (US government) | legal-risk:chief-legal-and-risk-officer, legal-risk:regulatory-compliance |
| Wage and Hour Division | US Department of Labor | Public domain (US government) | people:chief-human-resources-officer, people:employment-compliance, people:payroll-operations |
| govinfo | US Government Publishing Office | Public domain (US government) | legal-risk:regulatory-compliance |
Marketing and advertising
| Source | Publisher | License | Skills |
|---|---|---|---|
| .com Disclosures: How to Make Effective Disclosures in Digital Advertising | US Federal Trade Commission | Public domain (US government) | demand-generation:landing-page-cro-expert, demand-generation:lead-capture, demand-generation:paid-advertising, marketing:marketing-copywriting |
| ASA Statement on Statistical Significance and P-Values | American Statistical Association | Free to read, all rights reserved | demand-generation:experimentation, demand-generation:landing-page-cro-expert, demand-generation:marketing-analytics |
| App Store Review Guidelines | Apple | Free to read, all rights reserved | demand-generation:app-store-optimization, marketing:product-launch, product:chief-product-officer, revenue:pricing-and-packaging |
| CAN-SPAM Act: A Compliance Guide for Business | US Federal Trade Commission | Public domain (US government) | demand-generation:account-based-marketing, demand-generation:lead-capture, demand-generation:lifecycle-messaging, marketing:newsletter-writer, revenue:outbound-prospecting |
| Canada's Anti-Spam Legislation, S.C. 2010 c. 23 | Department of Justice Canada | Free to use with attribution | demand-generation:lead-capture, demand-generation:lifecycle-messaging, marketing:newsletter-writer, revenue:outbound-prospecting |
| Children's Online Privacy Protection Rule, 16 CFR 312 | US Federal Trade Commission | Public domain (US government) | demand-generation:app-store-optimization, demand-generation:lead-capture, demand-generation:paid-advertising, marketing:behavioral-marketing, product:product-requirements |
| Delivery restrictions and telephone solicitation rules, 47 CFR 64.1200 | US Federal Communications Commission | Public domain (US government) | demand-generation:lead-capture, demand-generation:lifecycle-messaging, marketing:behavioral-marketing, revenue:outbound-prospecting |
| Disclosures 101 for Social Media Influencers | US Federal Trade Commission | Public domain (US government) | marketing:partnership-marketing, marketing:social-post-craft, marketing:video-content, marketing:youtube-producer |
| FTC Business Guidance: Advertising and Marketing | US Federal Trade Commission | Public domain (US government) | marketing:chief-marketing-officer, marketing:marketing-campaign-planner, marketing:marketing-planning |
| Google Play Developer Program Policy | Free to read, all rights reserved | demand-generation:app-store-optimization, marketing:product-launch | |
| Google crawlers and user-triggered fetchers | CC BY | demand-generation:ai-search-optimization, demand-generation:programmatic-seo, demand-generation:seo-strategy | |
| Guide to PECR: cookies and similar technologies | UK Information Commissioner's Office | Free to use with attribution | demand-generation:experimentation, demand-generation:marketing-analytics, marketing:behavioral-marketing |
| Guidelines 05/2020 on consent under Regulation 2016/679 | European Data Protection Board | Free to use with attribution | demand-generation:landing-page-cro-expert, demand-generation:lead-capture, demand-generation:marketing-analytics, marketing:behavioral-marketing |
| Guides Against Deceptive Pricing, 16 CFR 233 | US Federal Trade Commission | Public domain (US government) | demand-generation:landing-page-cro-expert, demand-generation:paid-advertising, marketing:marketing-copywriting, revenue:pricing-and-packaging |
| Guides Concerning the Use of Endorsements and Testimonials in Advertising, 16 CFR 255 | US Federal Trade Commission | Public domain (US government) | marketing:partnership-marketing, marketing:public-relations, marketing:social-post-craft, marketing:youtube-producer, revenue:referral-programs |
| MRC standards and guidelines | Media Rating Council | Free to read, all rights reserved | demand-generation:marketing-analytics, demand-generation:paid-advertising, marketing:video-content |
| Native Advertising: A Guide for Businesses | US Federal Trade Commission | Public domain (US government) | demand-generation:paid-advertising, marketing:content-strategy, marketing:partnership-marketing, marketing:public-relations |
| Policy Statement Regarding Advertising Substantiation | US Federal Trade Commission | Public domain (US government) | demand-generation:paid-advertising, marketing:marketing-copywriting, marketing:positioning-and-messaging, marketing:product-launch |
| Product data specification | Free to read, all rights reserved | demand-generation:listing-distribution, demand-generation:paid-advertising | |
| RFC 9309: Robots Exclusion Protocol | IETF | Free to read, all rights reserved | demand-generation:ai-search-optimization, demand-generation:programmatic-seo, demand-generation:seo-strategy |
| Schema.org vocabulary | Schema.org community group | CC BY-SA (share-alike) | demand-generation:listing-distribution, demand-generation:programmatic-seo, demand-generation:seo-strategy |
| Spam policies for Google web search | CC BY | demand-generation:ai-search-optimization, demand-generation:programmatic-seo, demand-generation:seo-strategy, marketing:content-strategy | |
| Standard Definitions: final dispositions of case codes and outcome rates for surveys | American Association for Public Opinion Research | Free to read, all rights reserved | demand-generation:marketing-analytics, marketing:customer-research |
| Structured data markup that Google Search supports | CC BY | demand-generation:listing-distribution, demand-generation:programmatic-seo, demand-generation:seo-strategy | |
| Web Content Accessibility Guidelines 2.2 | World Wide Web Consortium | Free to read, all rights reserved | customer-experience:self-service-and-knowledge, demand-generation:landing-page-cro-expert, marketing:newsletter-writer, marketing:video-content, marketing:visual-content, product:design-system, product:interface-craft, product:interface-redesign, product:ux-product-auditor |
Pmo and operations
| Source | Publisher | License | Skills |
|---|---|---|---|
| 17 CFR Part 243 — Regulation FD | US Securities and Exchange Commission | Public domain (US government) | executive:fundraising-and-investor-relations, legal-risk:corporate-governance |
| 2010 ADA Standards for Accessible Design | US Department of Justice | Public domain (US government) | marketing:events-and-field-marketing, operations:facilities-and-workplace |
| 21 CFR Part 117 — preventive controls for human food | US Food and Drug Administration | Public domain (US government) | operations:procurement-and-sourcing, operations:quality-management, operations:supply-chain-and-logistics |
| 29 CFR Part 1910 — occupational safety and health standards | US Occupational Safety and Health Administration | Public domain (US government) | operations:facilities-and-workplace, people:learning-and-development |
| 49 CFR Part 395 — hours of service of drivers | Federal Motor Carrier Safety Administration | Public domain (US government) | operations:capacity-and-demand-planning, operations:supply-chain-and-logistics |
| 9 CFR Part 417 — Hazard Analysis and Critical Control Point systems | US Department of Agriculture, Food Safety and Inspection Service | Public domain (US government) | operations:process-design, operations:quality-management |
| Country Commercial Guides | US Department of Commerce, International Trade Administration | Public domain (US government) | corporate-strategy:market-entry, operations:supply-chain-and-logistics |
| Delaware General Corporation Law | State of Delaware | Public domain | executive:chief-executive, executive:fundraising-and-investor-relations, legal-risk:corporate-governance |
| Exempt offerings and Regulation D | US Securities and Exchange Commission | Public domain (US government) | executive:chief-executive, executive:fundraising-and-investor-relations |
| Federal Acquisition Regulation | US General Services Administration, on behalf of the FAR Council | Public domain (US government) | finance:cost-accounting, operations:procurement-and-sourcing, operations:vendor-management |
| GAO Agile Assessment Guide | US Government Accountability Office | Public domain (US government) | pmo:change-and-adoption, pmo:head-of-pmo, pmo:project-delivery |
| GAO Cost Estimating and Assessment Guide | US Government Accountability Office | Public domain (US government) | pmo:estimating-and-contingency, pmo:portfolio-governance, pmo:program-management |
| GAO Schedule Assessment Guide: best practices for project schedules | US Government Accountability Office | Public domain (US government) | pmo:dependency-and-risk-management, pmo:project-delivery, pmo:schedule-development-and-analysis |
| Hart-Scott-Rodino premerger notification program | US Federal Trade Commission | Public domain (US government) | corporate-strategy:chief-strategy-officer, corporate-strategy:mergers-and-acquisitions |
| ISO 9001 — Quality management systems: requirements | ISO | Sold | operations:process-design, operations:quality-management, operations:vendor-management |
| Incoterms rules | International Chamber of Commerce | Sold | operations:procurement-and-sourcing, operations:supply-chain-and-logistics |
| Interagency Guidance on Third-Party Relationships: Risk Management | Federal Reserve, FDIC and OCC | Public domain (US government) | operations:procurement-and-sourcing, operations:service-level-management, operations:vendor-management |
| Merger Guidelines | US Department of Justice and Federal Trade Commission | Public domain (US government) | corporate-strategy:chief-strategy-officer, corporate-strategy:mergers-and-acquisitions, corporate-strategy:portfolio-strategy |
| NASA Systems Engineering Handbook | NASA | Public domain (US government) | pmo:portfolio-governance, pmo:program-management, pmo:project-delivery |
| NIST SP 800-61: Incident Response Recommendations and Considerations | NIST | Public domain (US government) | customer-experience:escalation-management, operations:incident-management, security:detection-and-monitoring, security:incident-response |
| National Incident Management System doctrine | Federal Emergency Management Agency | Public domain (US government) | operations:business-continuity-and-resilience, operations:incident-management |
| The Green Book: appraisal and evaluation in central government | HM Treasury | Free to use with attribution | corporate-strategy:portfolio-strategy, pmo:benefits-realization, pmo:estimating-and-contingency, pmo:portfolio-governance |
Revenue and product
| Source | Publisher | License | Skills |
|---|---|---|---|
| 15 U.S.C. 7001 — Electronic Signatures in Global and National Commerce Act | US Congress, via the Office of the Law Revision Counsel | Public domain (US government) | customer-experience:customer-onboarding-and-implementation, revenue:deal-negotiation, revenue:revenue-operations |
| 15 U.S.C. 8403 — Restore Online Shoppers' Confidence Act | US Congress, via the Office of the Law Revision Counsel | Public domain (US government) | product:product-requirements, revenue:activation, revenue:pricing-and-packaging, revenue:retention |
| 16 CFR Part 310 — Telemarketing Sales Rule | US Federal Trade Commission | Public domain (US government) | revenue:outbound-prospecting, revenue:revenue-operations, revenue:sales-enablement |
| 18 U.S.C. 2511 — interception of communications | US Congress, via the Office of the Law Revision Counsel | Public domain (US government) | customer-experience:support-operations, revenue:outbound-prospecting |
| 36 CFR Part 1194 — Section 508 information and communication technology standards | US Access Board | Public domain (US government) | product:product-requirements, product:ux-product-auditor, revenue:sales-enablement |
| Age Appropriate Design Code | UK Information Commissioner's Office | Free to use with attribution | product:interface-craft, product:product-requirements, revenue:activation |
| CCPA regulations, California Code of Regulations title 11 | California Privacy Protection Agency | Public domain | marketing:behavioral-marketing, product:interface-craft, product:interface-redesign, product:ux-product-auditor |
| California Automatic Renewal Law, Business and Professions Code 17600-17606 | California Legislative Counsel | Public domain | product:interface-craft, product:product-requirements, revenue:pricing-and-packaging, revenue:retention |
| California Labor Code 2751 — commission agreements in writing | California Legislative Counsel | Public domain | revenue:revenue-operations, revenue:sales-compensation-and-territory |
| Commission Guidance on Management's Discussion and Analysis, Release 33-10751 | US Securities and Exchange Commission | Public domain (US government) | data-analytics:business-intelligence, finance:unit-economics, revenue:revenue-operations |
| Compendium of U.S. Copyright Office Practices | US Copyright Office | Public domain (US government) | legal-risk:intellectual-property, product:brand-identity, product:visual-reference-generation |
| EN 301 549 — accessibility requirements for ICT products and services | ETSI | Free to read, all rights reserved | product:product-requirements, product:ux-product-auditor, revenue:sales-enablement |
| Fact Sheet 17F: exemption for outside sales employees | US Department of Labor, Wage and Hour Division | Public domain (US government) | people:employment-compliance, revenue:sales-compensation-and-territory |
| Federal Plain Language Guidelines | Plain Language Action and Information Network | Public domain (US government) | customer-experience:self-service-and-knowledge, customer-experience:support-operations |
| Human Interface Guidelines | Apple | Free to read, all rights reserved | product:design-system, product:interface-craft, product:interface-redesign |
| Non-GAAP financial measures — compliance and disclosure interpretations | US Securities and Exchange Commission, Division of Corporation Finance | Public domain (US government) | finance:capital-structure-and-covenants, finance:unit-economics |
| PCI Data Security Standard | PCI Security Standards Council | Free behind an account | customer-experience:support-operations, security:data-protection-and-encryption, security:detection-and-monitoring |
| Regulation (EU) 910/2014 — eIDAS | Publications Office of the European Union | Free to use with attribution | revenue:deal-negotiation, revenue:revenue-operations |
| SIL Open Font License | SIL International | Free to read, all rights reserved | product:brand-identity, product:design-system |
| Trademark Manual of Examining Procedure | US Patent and Trademark Office | Public domain (US government) | legal-risk:intellectual-property, product:brand-identity |
| Unicode Common Locale Data Repository | Unicode Consortium | Free to use with attribution | product:design-system, product:interface-craft, product:product-requirements |
| Uniform Commercial Code, Article 2 — Sales | American Law Institute and Uniform Law Commission | Free to read, all rights reserved | revenue:deal-negotiation, revenue:revenue-operations |
| WAI-ARIA and the ARIA Authoring Practices Guide | World Wide Web Consortium | Free to read, all rights reserved | product:design-system, product:interface-craft, product:interface-redesign, product:ux-product-auditor |
Security
| Source | Publisher | License | Skills |
|---|---|---|---|
| CIS Critical Security Controls | Center for Internet Security | Free behind an account | security:chief-information-security-officer |
| CISA Known Exploited Vulnerabilities Catalog | CISA | Public domain (US government) | security:incident-response, security:vulnerability-management |
| FedRAMP baselines and automation content | GSA | Public domain (US government) | legal-risk:regulatory-compliance, security:chief-information-security-officer, security:security-architecture-review |
| ISO/IEC 27001 — Information security management systems | ISO | Sold | legal-risk:regulatory-compliance, security:chief-information-security-officer |
| MITRE ATT&CK | The MITRE Corporation | Free to use with attribution | security:detection-and-monitoring, security:incident-response, security:security-architecture-review, security:threat-modeling |
| NIST Cybersecurity Framework 2.0 | NIST | Public domain (US government) | security:chief-information-security-officer, security:security-architecture-review |
| NIST SP 800-53 Rev. 5 — Security and Privacy Controls for Information Systems | NIST | Public domain (US government) | security:access-and-identity, security:chief-information-security-officer, security:security-architecture-review |
| National Vulnerability Database | NIST | Public domain (US government) | security:vulnerability-management |
| OWASP Application Security Verification Standard | OWASP Foundation | CC BY-SA (share-alike) | security:security-architecture-review |
| OWASP Top 10 | OWASP Foundation | CC BY-SA (share-alike) | security:security-architecture-review, security:threat-modeling |
| SANS Information Security Policy Templates | SANS Institute | Free to read, all rights reserved | legal-risk:regulatory-compliance, security:chief-information-security-officer |
Technology and it
| Source | Publisher | License | Skills |
|---|---|---|---|
| 47 CFR Part 9 — 911 requirements | US Federal Communications Commission | Public domain (US government) | it-operations:telephony-and-conferencing |
| AWS Well-Architected Framework | Amazon Web Services | Free to read, all rights reserved | it-operations:cloud-administration, technology:cloud-infrastructure, technology:solution-architecture |
| Agent Skills documentation | Anthropic | Free to read, all rights reserved | technology:skill-authoring |
| Automated Technical Debt Measure | Object Management Group | Free to read, all rights reserved | technology:technical-debt-management |
| Azure Well-Architected Framework | Microsoft | Free to read, all rights reserved | it-operations:cloud-administration, technology:cloud-infrastructure |
| CIS Benchmarks | Center for Internet Security | Free behind an account | it-operations:cloud-administration, it-operations:endpoint-management, it-operations:systems-administration, it-operations:virtualization-operations |
| Conventional Commits 1.0.0 | Conventional Commits project | CC BY | technology:branch-and-worktree-workflow |
| Git reference manual | Git project | Free to read, all rights reserved | technology:branch-and-worktree-workflow, technology:parallel-agent-delivery |
| Google Cloud Architecture Framework | Google Cloud | Free to read, all rights reserved | it-operations:cloud-administration, technology:cloud-infrastructure |
| Model Context Protocol specification | Model Context Protocol project | Free to read, all rights reserved | technology:ai-workflow-architect |
| NIST SP 1800-5: IT Asset Management | NIST / National Cybersecurity Center of Excellence | Public domain (US government) | it-operations:chief-information-officer, it-operations:it-asset-management |
| NIST SP 800-124: Guidelines for Managing the Security of Mobile Devices | NIST | Public domain (US government) | it-operations:endpoint-management |
| NIST SP 800-145: The NIST Definition of Cloud Computing | NIST | Public domain (US government) | it-operations:cloud-administration, technology:cloud-infrastructure |
| NIST SP 800-207: Zero Trust Architecture | NIST | Public domain (US government) | it-operations:cloud-administration, it-operations:identity-lifecycle-administration, it-operations:network-administration |
| NIST SP 800-34: Contingency Planning Guide for Federal Information Systems | NIST | Public domain (US government) | it-operations:backup-and-recovery, operations:business-continuity-and-resilience, operations:incident-management |
| NIST SP 800-40: Guide to Enterprise Patch Management Planning | NIST | Public domain (US government) | it-operations:endpoint-management, it-operations:systems-administration, security:vulnerability-management |
| NIST SP 800-63: Digital Identity Guidelines | NIST | Public domain (US government) | it-operations:identity-lifecycle-administration, security:access-and-identity |
| OpenAPI Specification | OpenAPI Initiative, Linux Foundation | Free to use with attribution | technology:api-design |
| OpenID Connect Core 1.0 | OpenID Foundation | Free to read, all rights reserved | it-operations:identity-lifecycle-administration |
| OpenTelemetry specification and semantic conventions | OpenTelemetry project, Cloud Native Computing Foundation | CC BY | technology:observability-and-reliability |
| RFC 1035: Domain Names — Implementation and Specification | IETF | Free to read, all rights reserved | it-operations:network-administration |
| RFC 1918: Address Allocation for Private Internets | IETF | Free to read, all rights reserved | it-operations:network-administration |
| RFC 3261: SIP — Session Initiation Protocol | IETF | Free to read, all rights reserved | it-operations:telephony-and-conferencing |
| RFC 7644: System for Cross-domain Identity Management Protocol | IETF | Free to read, all rights reserved | it-operations:identity-lifecycle-administration |
| RFC 9110: HTTP Semantics | IETF | Free to read, all rights reserved | technology:api-design |
| RFC 9457: Problem Details for HTTP APIs | IETF | Free to read, all rights reserved | technology:api-design |
| RFC 9700: Best Current Practice for OAuth 2.0 Security | IETF | Free to read, all rights reserved | it-operations:identity-lifecycle-administration, technology:api-design |
| Regulation (EU) 2024/1689 — the AI Act | Publications Office of the European Union | Free to use with attribution | data-analytics:ai-ml-governance, legal-risk:regulatory-compliance, technology:chief-technology-officer |
| Secure Cloud Business Applications (SCuBA) | CISA | Public domain (US government) | it-operations:collaboration-platform-administration |
| Security Technical Implementation Guides | Defense Information Systems Agency, US Department of Defense | Public domain (US government) | it-operations:endpoint-management, it-operations:network-administration, it-operations:systems-administration, it-operations:virtualization-operations |
| Semantic Versioning 2.0.0 | Semantic Versioning project | CC BY | technology:api-design, technology:branch-and-worktree-workflow |
| Site Reliability Engineering and The SRE Workbook | Free to read, all rights reserved | technology:observability-and-reliability | |
| Trace Context | World Wide Web Consortium | Free to read, all rights reserved | technology:observability-and-reliability |
| WebRTC: Real-Time Communication in Browsers | World Wide Web Consortium | Free to read, all rights reserved | it-operations:telephony-and-conferencing |
Keeping it honest
scripts/check-sources.py runs on every push and verifies structure, the license vocabulary, that every skill named resolves, and that a skill with sources actually points at them. Reachability is checked weekly by its own workflow instead, because a publisher being briefly down is not a reason to fail an unrelated pull request.
Sources are maintained in sources/*.toml. See sources/README.md for the format and the full license vocabulary.